CVE-2020-13940
published 2020-10-01CVE-2020-13940: In Apache NiFi 1.0.0 to 1.11.4, the notification service manager and various policy authorizer and user group provider objects allowed trusted administrators…
PriorityP427medium5.5CVSS 3.1
AVLACLPRNUIRSUCHINAN
EPSS
1.91%
77.4th percentile
In Apache NiFi 1.0.0 to 1.11.4, the notification service manager and various policy authorizer and user group provider objects allowed trusted administrators to inadvertently configure a potentially malicious XML file. The XML file has the ability to make external calls to services (via XXE).
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | nifi | — | — |
| apache | nifi | 1.0.0 – 1.11.4 | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_apache5.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Improper Restriction of XML External Entity Reference in Apache NiFi
ghsa·2022-01-06
CVE-2020-13940 [MEDIUM] CWE-611 Improper Restriction of XML External Entity Reference in Apache NiFi
Improper Restriction of XML External Entity Reference in Apache NiFi
In Apache NiFi 1.0.0 to 1.11.4, the notification service manager and various policy authorizer and user group provider objects allowed trusted administrators to inadvertently configure a potentially malicious XML file. The XML file has the ability to make external calls to services (via XXE).
OSV
Improper Restriction of XML External Entity Reference in Apache NiFi
osv·2022-01-06
CVE-2020-13940 [MEDIUM] Improper Restriction of XML External Entity Reference in Apache NiFi
Improper Restriction of XML External Entity Reference in Apache NiFi
In Apache NiFi 1.0.0 to 1.11.4, the notification service manager and various policy authorizer and user group provider objects allowed trusted administrators to inadvertently configure a potentially malicious XML file. The XML file has the ability to make external calls to services (via XXE).
Apache
Apache nifi: CVE-2020-13940
vendor_apache·CVSS 5.5
CVE-2020-13940 [LOW] Apache nifi: CVE-2020-13940
Apache nifi: CVE-2020-13940
Title: Potential Information Disclosure through XML External Entity Resolution in Notification Service Published: 2020-08-18 Severity: Low Products: Apache NiFi Affected Versions: 1.0.0 to 1.11.4 Fixed Versions: 1.12.0 Reporter: Matt Burgess and Andy LoPresto References CVE Record: CVE-2020-13940 NVD Record: CVE-2020-13940 Apache Jira Issue: NIFI-7680 GitHub Pull Request: 4436 The notification service manager and various policy authorizer and user group provider objects allowed trusted administrators to inadvertently configure a potentially malicious XML file. The XML file has the ability to make external calls to services through XML External Entity resolution. NiFi 1.12.0 introduced an XML validator to prevent malicious code from being parsed and executed. Use
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-10-01
Published